exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Asterisk Project Security Advisory - AST-2019-004

Asterisk Project Security Advisory - AST-2019-004
Posted Sep 5, 2019
Authored by Alexei Gradinari | Site asterisk.org

Asterisk Project Security Advisory - When Asterisk sends a re-invite initiating T.38 faxing, and the endpoint responds with a declined media stream a crash will then occur in Asterisk.

tags | advisory
advisories | CVE-2019-15297
SHA-256 | bb7ad078a0f3af2b1a5200e64d077cdaa043b5c90eed178634116a901bf0a64c

Asterisk Project Security Advisory - AST-2019-004

Change Mirror Download
               Asterisk Project Security Advisory - AST-2019-004

Product Asterisk
Summary Crash when negotiating for T.38 with a declined
stream
Nature of Advisory Remote Crash
Susceptibility Remote Authenticated Sessions
Severity Minor
Exploits Known No
Reported On August 05, 2019
Reported By Alexei Gradinari
Posted On September 05, 2019
Last Updated On September 4, 2019
Advisory Contact kharwell AT sangoma DOT com
CVE Name CVE-2019-15297

Description When Asterisk sends a re-invite initiating T.38
faxing, and the endpoint responds with a declined
media stream a crash will then occur in Asterisk.
Modules Affected res_pjsip_t38.c

Resolution If T.38 faxing is not required then setting the “t38_udptl”
configuration option on the endpoint to “no” disables this
functionality. This option defaults to “no” so you have to
have explicitly set it “yes” to potentially be affected by
this issue.

Otherwise, if T.38 faxing is required then Asterisk should
be upgraded to a fixed version.

Affected Versions
Product Release Series
Asterisk Open Source 15.x All releases
Asterisk Open Source 16.x All releases

Corrected In
Product Release
Asterisk Open Source 15.7.4,16.5.1

Patches
SVN URL Revision
http://downloads.asterisk.org/pub/security/AST-2019-004-15.diff Asterisk
15
http://downloads.asterisk.org/pub/security/AST-2019-004-16.diff Asterisk
16

Links https://issues.asterisk.org/jira/browse/ASTERISK-28495

Asterisk Project Security Advisories are posted at
http://www.asterisk.org/security

This document may be superseded by later versions; if so, the latest
version will be posted at
http://downloads.digium.com/pub/security/AST-2019-004.pdf and
http://downloads.digium.com/pub/security/AST-2019-004.html

Revision History
Date Editor Revisions Made
August 28, 2019 Kevin Harwell Initial revision

Asterisk Project Security Advisory - AST-2019-004
Copyright © 2019 Digium, Inc. All Rights Reserved.
Permission is hereby granted to distribute and publish this advisory in its
original, unaltered form.
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    6 Files
  • 19
    Jul 19th
    34 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    19 Files
  • 23
    Jul 23rd
    17 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close